MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb3292555a7607f5861b24d8e766257f9990644a06cd2eaefb4075357d8ef386. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fb3292555a7607f5861b24d8e766257f9990644a06cd2eaefb4075357d8ef386
SHA3-384 hash: bb12f536f12a6fc30fb11085addefc5be7e0c32af813c72ac18c102b15f3991801f99b1e19e796f58b48332d13196884
SHA1 hash: bc62bd119cd2f57590664ae237ac4bef569fff61
MD5 hash: 06eafdaa87cc5c8f16a9540febc9ef74
humanhash: spaghetti-robert-juliet-louisiana
File name:DOC982761717.DOC.zip
Download: download sample
Signature Formbook
File size:523'144 bytes
First seen:2022-03-01 08:19:08 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:rlm87WAskGJLIfn0Iu+45OMUQoh8ZHuXg+r9AHZcHsIu:rll7p/GJL0qqMUvkgyHZVIu
TLSH T1D8B423E09642CE43CB355CB75B423F4DEDF1BD6A06B3899C69B859B0001EF41C2DA98B
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email (T1566.001)
From: "info@cordeel.bg" (likely spoofed)
Received: "from ws01.fastweb.ro (unknown [193.169.145.11]) "
Date: "Mon, 28 Feb 2022 07:52:00 +0100"
Subject: "=?UTF-8?Q?RE=3A_=5BEXTERNAL=5D_RE=3A_=D0=9D=D0=BE=D0=B2=D0=B0_?=
=?UTF-8?Q?=D0=BF=D0=BE=D1=80=D1=8A=D1=87=D0=BA=D0=B0=2C?="
Attachment: "DOC982761717.DOC.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe keylogger packed replace.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2022-02-28 13:30:58 UTC
File Type:
Binary (Archive)
Extracted files:
48
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip fb3292555a7607f5861b24d8e766257f9990644a06cd2eaefb4075357d8ef386

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments